Back to skill

Security audit

商业自动中枢

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent business-automation guide, but its templates include high-impact financial automation with auto-approval and recurring execution patterns that need careful review before use.

Install only if you intend to build business automations and are prepared to review every production action. Keep finance, payment, CRM, publishing, and account-provisioning workflows in dry-run until explicit human approvals, allowlisted recipients, least-privilege credentials, audit logs, and fail-closed timeout behavior are configured.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:389
Finding

Fail-Open Approval Timeout Permits Transactions Without Affirmative Authorization

Content
View full analysis
5000 OR new_vendor = true" action: - Send an approval request through Slack/email - Include: summary, amount, context, approve/reject buttons - Deadline: 24 hours on_approve: continue_workflow on_reject: notify_requestor_with_reason on_timeout: - Escalate to a superior - Or: automatically approve when amount < 10000 ``` The snippet is an English rendering of the original workflow template while preserving its logic and thresholds. ### Technical Analysis The approval gate uses fail-open behavior: a transaction that initially requires human review can be approved solely because the approval request times out. A timeout does not demonstrate authorization and may result from an unavailable approver, message-delivery failure, routing error, notification suppression, or intentional delay. The rule also creates inconsistent authorization boundaries. Transactions over 5,000 and transactions involving new vendors require approval initially, but transactions below 10,000 may later bypass that requirement without an affirmative decision. Because this project is an instructional Skill rather than an executable implementation, the issue affects workflows generated or configured according to this template. No evidence was found that the repository itself directly executes a transaction. ### Attack Path 1. An attacker or untrusted requester submits a transaction that triggers manager review, such as a new-vendor transaction below 10,000. 2. The workflow sends an approval request and waits for 24 hours. 3. The attacker waits for expiration or attempts to cause the approval request to be overlooked, delayed, suppressed, or misrouted. 4. The timeout branch is reached wit ...[truncated 954 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:393
Finding

Sensitive Financial Context Is Sent Through Notification Channels Without Defined Security Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The workflow template includes automatic approval for invoices at or below a threshold, which is autonomous decision-making over a financially sensitive process. In context, this is more dangerous because the same skill promotes end-to-end automation with OCR extraction, routing, scheduling, notifications, and external system updates; if the parsed data is wrong, spoofed, or incomplete, the agent could approve and post transactions without adequate human verification.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
type: condition
      rules:
        - condition: "amount <= 5000"
          goto: auto_approve
        - condition: "default"
          goto: manager_review
  error_handling:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill describes implementation patterns involving exec, curl/python/jq, cron scheduling, storage, and messaging, but it does not present an upfront warning that these automations can execute commands, write persistent artifacts, and interact with third-party systems. That omission can mislead users into treating the skill as advisory-only when it actually supports operational behavior with real-world side effects, increasing the chance of unsafe or unintended execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The quick-start triggers are broad enough to match ordinary automation requests and can cause the skill to engage in high-impact workflow design or execution without first establishing scope, safety boundaries, or whether external actions are permitted. In this skill, that risk is amplified because the document explicitly maps tasks to exec, cron, file writes, notifications, and external integrations, so a casual user prompt could lead to actionable automation plans or agent-driven side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description states '所有模板中文化', and the entire skill is written to operate in Chinese without indicating that users may choose another language. This can violate language-choice policy when a skill imposes a locale by default rather than offering opt-in or alternatives.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.